Skip to content

Security: ajitpratap0/nebula

Security

SECURITY.md

Security Policy

Supported Versions

We currently support security updates for the following versions:

Version Supported
0.3.x
< 0.3

Reporting a Vulnerability

We take security seriously. If you discover a security vulnerability, please report it responsibly.

How to Report

  1. Do NOT create a public GitHub issue for security vulnerabilities
  2. Email security concerns to: [email protected]
  3. Include detailed information about the vulnerability
  4. Provide steps to reproduce the issue if possible

What to Include

  • Description of the vulnerability
  • Steps to reproduce the issue
  • Potential impact assessment
  • Suggested fixes (if any)
  • Your contact information

Response Timeline

  • Acknowledgment: Within 48 hours
  • Initial Assessment: Within 1 week
  • Status Updates: Weekly until resolved
  • Resolution: Depends on severity and complexity

Security Best Practices

When using Nebula in production:

  1. Keep Updated: Use the latest stable version
  2. Secure Configuration: Follow configuration guidelines
  3. Network Security: Implement proper firewall rules
  4. Access Control: Use appropriate authentication
  5. Monitoring: Monitor for unusual activity
  6. Data Protection: Encrypt sensitive data in transit and at rest

Scope

This security policy covers:

  • Core Nebula application
  • Official connectors
  • Configuration and deployment guides
  • Dependencies with known vulnerabilities

Out of Scope

  • Third-party connectors
  • Custom configurations
  • Infrastructure security
  • Social engineering attacks

Thank you for helping keep Nebula secure!

There aren’t any published security advisories